RFC 7646: Definition and Use of DNSSEC Negative Trust Anchors
In plain English — editorial summary, not part of the RFC
DNS Security Extensions (DNSSEC) is now entering widespread deployment. However, domain signing tools and processes are not yet as mature and reliable as those for non-DNSSEC-related domain administration tools and processes. This document defines Negative Trust Anchors (NTAs), which can be used to mitigate DNSSEC validation failures by disabling DNSSEC validation at specified domains.
Document record
- Document ID
- RFC7646
- Published
- September 2015
- Authors
- P. Ebersman; W. Kumari; C. Griffiths; J. Livingood; R. Weber
- Status
- INFORMATIONAL
- Stream
- IETF
- Area
- ops
- Pages
- 16
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 7828The edns-tcp-keepalive EDNS0 OptionCurrent
April 2016
- RFC 7344Automating DNSSEC Delegation Trust MaintenanceUpdated
September 2014
- RFC 8027DNSSEC Roadblock AvoidanceCurrent
November 2016
- RFC 8145Signaling Trust Anchor Knowledge in DNS Security Extensions (DNSSEC)Updated
April 2017
- RFC 6841A Framework for DNSSEC Policies and DNSSEC Practice StatementsCurrent
January 2013
- RFC 8509A Root Key Trust Anchor Sentinel for DNSSECCurrent
December 2018
- RFC 8749Moving DNSSEC Lookaside Validation (DLV) to Historic StatusCurrent
March 2020
- RFC 8976Message Digest for DNS ZonesCurrent
February 2021
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?